async function allowCORS(ctx, next) {
    console.log(ctx.headers['origin']);
    ctx.set({
        "Access-Control-Allow-Origin": ctx.headers['origin'],
        "Access-Control-Allow-Methods": "GET,HEAD,PUT,POST,DELETE,PATCH,OPTIONS",
        "Access-Control-Allow-Headers": "Origin, X-Requested-With, Content-Type, Accept, Authorization",
        "Access-Control-Expose-Headers": "Content-Length, Content-Type, Authorization",
        "Access-Control-Allow-Credentials": "true",
       
        
    });  
    next();
}
module.exports = allowCORS;